CurNext

CurNext · Legal

Privacy Policy

How CurNext collects, uses, shares, and protects personal data on curnext.app, the CurNext dashboard, APIs, and related services - and how you can exercise your privacy rights.

Controller for CurNext account, marketing, and website data: CurNext (Finland). Processor for Client Data instructed through the platform: CurNext under a DPA. Privacy requests: [email protected]. Core production hosting: Germany / Frankfurt.

This Privacy Policy explains CurNext's personal-data practices for transparency. It works together with our GDPR Policies, Cookie Policy, Security Policy, and Data Processing Agreement. It is not legal advice. Where this page and a signed contract conflict, the signed contract controls for that relationship.

Last updated: 11 August 2026

Purpose of this policy

CurNext provides construction site intelligence using industrial IoT sensing and cloud software. Operating that stack involves personal data about website visitors, leads, invitees, admins, applicants, and support contacts.

  • - Identify who is responsible for which processing.
  • - Describe what personal data we collect and why.
  • - Explain legal bases, sharing, transfers, and retention at a policy level.
  • - Tell you how to exercise privacy rights and where cookies are covered.
  • - State age eligibility for product onboarding under internal policies.

Who we are

For personal data where CurNext determines the purposes and means of processing, the controller is:

  • CurNext
  • Registered in Finland
  • Business ID Coming soon
  • Website: https://curnext.app

Privacy and data subject requests: [email protected]. Data Processing Agreements: [email protected]. Security incidents and vulnerability disclosure: [email protected].

[email protected]

Controller and processor roles

Roles determine who answers a request about your data.

CurNext as controller

We are typically the controller for the marketing website, newsletters and product updates, contact and quote forms sent to CurNext, careers and recruitment, CurNext CRM and sales records, invite-only account identities we maintain to provide access, and telemetry needed to operate and secure CurNext products.

CurNext as processor

When a customer (the Client) uses CurNext to monitor sites and manage project users, CurNext generally acts as processor for Client Data under the Client's instructions. The Client remains the controller for that Client Data. Processor terms are in the Data Processing Agreement.

If you are unsure

Write to [email protected]. We will route the request to the right party or assist the Client controller when your request concerns project data they control.

Personal data we collect

Categories depend on how you interact with CurNext. Typical examples:

Identity and contact

Name, work email, phone, company, role, locale preference, and similar business contact details.

Account and access

Invite status, organisation or project membership, roles and permissions, authentication metadata, session and device signals used for security, and MFA status for privileged roles.

Commercial and support

Messages via contact, quote, demo, or support channels; ticket history; contract and billing references needed to serve the account.

Usage and technical

IP addresses, approximate location from network data, browser or user-agent, diagnostic logs, rate-limit and WAF events, and product usage metrics needed to operate the Services.

Recruitment

CV or résumé content, application answers, interview notes, and related communications for open roles.

Client-controlled project content

Notes, uploads, BIM-linked annotations, and collaborator lists inside customer projects. The Client controls this as controller; CurNext processes it as processor under documented instructions.

How we use personal data

We use personal data only for stated purposes, including:

Provide and secure the Services

Create and administer accounts, authenticate invitees, deliver dashboards and APIs, protect against abuse, and maintain auditability.

Respond to you

Answer contact, quote, demo, support, and partnership requests.

Communicate about the product

Send transactional messages related to your account or request, and optional product updates where permitted by law and your preferences.

Recruitment

Evaluate applications and run hiring processes for open roles.

Improve and operate

Diagnose issues, improve reliability, and develop features - without overriding your rights and freedoms.

Legal and compliance

Meet accounting, tax, and regulatory duties, and establish or defend legal claims.

Legal bases

Where GDPR applies, we rely on one or more of the following bases. Detail for specific features may also appear in GDPR Policies and contracts.

Contract

Creating accounts, delivering ordered Services, authenticating invitees, and performing quote or order workflows.

Legitimate interests

Securing the platform, improving reliability, B2B relationship management, limited product analytics that do not override rights and freedoms, and defending legal claims - with objection rights where required.

Consent

Non-essential cookies where consent is required, optional marketing emails where consent is the chosen basis, Knowledge Base AI chat consent flows, and other features we mark as consent-based.

Legal obligation

Tax, accounting, and regulatory record-keeping, lawful authority requests, and breach notification duties where CurNext is the controller.

Sharing and processors

We do not sell personal data. We share personal data with service providers who help us operate CurNext, and otherwise only when required or authorised.

  • - Hosting, database, email, payments, observability, and optional AI vendors under written terms - see the public subprocessor list on the DPA page.
  • - Cloudflare Turnstile for bot protection on forms.
  • - Professional advisors (legal, accounting) under confidentiality when needed.
  • - Authorities when required by law.
  • - A successor entity in connection with a corporate transaction, subject to appropriate protections.

International transfers

Core application and database hosting for the platform is designed around Germany / Frankfurt (EU). Commercial markets today include Finland, Canada, and Cameroon - selling into a market is not the same as hosting a local production region there.

  • - EEA / EU processing is the default for Client Data on the production stack unless a written enterprise residency addendum says otherwise.
  • - Transfers outside the EEA, if any, use tools such as Standard Contractual Clauses, adequacy decisions where applicable, and contractual or technical safeguards described in the DPA.
  • - Canadian and Cameroon customers access EU-hosted Client Data as instructed; the Client remains controller for that Client Data.

Retention

We keep personal data only as long as needed for the purposes described, including legal, accounting, and security needs.

  • - Account and service data: for the customer relationship and a wind-down period, then deleted or anonymised per product and DPA schedules.
  • - Marketing contacts: until you unsubscribe or object, or under list hygiene - suppression records may last longer so we do not email you again.
  • - Support and sales correspondence: as needed to complete the request and keep a reasonable business record.
  • - Recruitment: for the hiring process and a limited post-process period (or longer with consent for future roles).
  • - Security and GDPR audit events: sometimes longer, including append-only or pseudonymised forms - see Audit Trail.
  • - Backups: encrypted rolling retention; live deletion may take effect in backups only after the backup cycle expires.

Your privacy rights

Depending on your location and role, you may have rights to access, rectify, erase, restrict, port, or object to certain processing, and to withdraw consent where processing is based on consent.

  • - Email [email protected] from an address we can associate with you, or with enough detail to identify you.
  • - State which right you wish to exercise and the context (website, newsletter, dashboard, job application, or customer project).
  • - For Client Data inside a customer tenant, the Client is usually the first contact; we will assist under the DPA.
  • - You may also select GDPR / privacy on the contact form at /contact.
  • - You may lodge a complaint with a supervisory authority - for CurNext as a Finnish controller, typically the Office of the Data Protection Ombudsman (tietosuoja.fi).

We aim to respond without undue delay and within one month where GDPR applies, with extensions permitted for complex requests. We may need to verify identity before fulfilling a request.

Cookies and similar technologies

Cookies, local storage, and similar technologies are described in the Cookie Policy, including necessary and optional categories and how to change preferences with the on-site consent widget.

Cookie Policy

Security

We apply organisational and technical measures appropriate to the risk, including invite-only access, RBAC, privileged MFA, encryption in transit and at rest for core stores, and GDPR-oriented audit paths.

  • - Security Policy and Security architecture pages describe controls and disclosure.
  • - Report vulnerabilities to [email protected] using coordinated disclosure.
  • - We do not claim ISO 27001 or SOC 2 certification for CurNext on public pages unless separately confirmed in writing.

Children and age eligibility

CurNext Services are designed for professional construction and B2B use. They are not directed at children. Under CurNext internal policies, we do not onboard, invite, or register product users under 18 years of age. We also do not knowingly collect personal data from children under 16 for CurNext products. If you believe someone under 18 has been onboarded, or that a child has provided personal data, contact [email protected].

Markets we sell into

CurNext currently sells into Finland, Canada, and Cameroon on an EU-anchored production stack unless an enterprise residency addendum says otherwise.

  • - Finland / EEA: GDPR is the primary privacy regime for platform processing.
  • - Canada: Client remains controller for Client Data; PIPEDA and provincial rules may apply to the Client.
  • - Cameroon: Client remains controller for Client Data; local obligations may apply to the Client.

Changes to this policy

We may update this Privacy Policy when products, vendors, or law change. The Last updated date will change for material revisions. Continued use of the marketing site after an update constitutes awareness of the revised public policy text; contractual customers are governed by their agreements.

Translations are provided for convenience. Where a signed agreement exists, the English instrument controls.